PART 2
2007-03-02 11:42 <DIR> d-------- C:\WINDOWS\system32\Restore
2007-03-02 11:42 <DIR> d-------- C:\WINDOWS\system32\Macromed
2007-03-02 11:42 <DIR> d-------- C:\WINDOWS\srchasst
2007-03-02 11:42 <DIR> d-------- C:\Program Files\Movie Maker
2007-03-02 11:41 97,792 --a------ C:\WINDOWS\system32\comrepl.dll
2007-03-02 11:41 956,416 --a------ C:\WINDOWS\system32\msdtctm.dll
2007-03-02 11:41 93,696 --a------ C:\WINDOWS\system32\tscfgwmi.dll
2007-03-02 11:41 91,136 --a------ C:\WINDOWS\system32\mtxoci.dll
2007-03-02 11:41 9,728 --a------ C:\WINDOWS\system32\reset.exe
2007-03-02 11:41 87,176 --a------ C:\WINDOWS\system32\rdpwsx.dll
2007-03-02 11:41 85,504 --a------ C:\WINDOWS\system32\catsrvps.dll
2007-03-02 11:41 80,384 --a------ C:\WINDOWS\system32\charmap.exe
2007-03-02 11:41 73,216 --a------ C:\WINDOWS\system32\avwav.dll
2007-03-02 11:41 67,072 --a------ C:\WINDOWS\system32\rdshost.exe
2007-03-02 11:41 655,360 --a------ C:\WINDOWS\system32\mstscax.dll
2007-03-02 11:41 625,152 --a------ C:\WINDOWS\system32\catsrvut.dll
2007-03-02 11:41 62,464 --a------ C:\WINDOWS\system32\rdpclip.exe
2007-03-02 11:41 605,696 --a------ C:\WINDOWS\system32\getuname.dll
2007-03-02 11:41 60,416 --a------ C:\WINDOWS\system32\remotepg.dll
2007-03-02 11:41 60,416 --a------ C:\WINDOWS\system32\colbact.dll
2007-03-02 11:41 6,144 --a------ C:\WINDOWS\system32\msdtc.exe
2007-03-02 11:41 58,880 --a------ C:\WINDOWS\system32\msdtclog.dll
2007-03-02 11:41 56,832 --a------ C:\WINDOWS\system32\sol.exe
2007-03-02 11:41 55,296 --a------ C:\WINDOWS\system32\freecell.exe
2007-03-02 11:41 540,160 --a------ C:\WINDOWS\system32\comuid.dll
2007-03-02 11:41 54,272 --a------ C:\WINDOWS\system32\stclient.dll
2007-03-02 11:41 538,624 --a------ C:\WINDOWS\system32\spider.exe
2007-03-02 11:41 5,632 --a------ C:\WINDOWS\system32\write.exe
2007-03-02 11:41 5,120 --a------ C:\WINDOWS\system32\dcomcnfg.exe
2007-03-02 11:41 498,688 --a------ C:\WINDOWS\system32\clbcatq.dll
2007-03-02 11:41 44,544 --a------ C:\WINDOWS\system32\tscupgrd.exe
2007-03-02 11:41 44,544 --a------ C:\WINDOWS\system32\hticons.dll
2007-03-02 11:41 426,496 --a------ C:\WINDOWS\system32\msdtcprx.dll
2007-03-02 11:41 407,552 --a------ C:\WINDOWS\system32\mstsc.exe
2007-03-02 11:41 4,096 --a------ C:\WINDOWS\system32\rdpcfgex.dll
2007-03-02 11:41 4,096 --a------ C:\WINDOWS\system32\mtxex.dll
2007-03-02 11:41 38,912 --a------ C:\WINDOWS\system32\cfgbkend.dll
2007-03-02 11:41 35,328 --a------ C:\WINDOWS\system32\winchat.exe
2007-03-02 11:41 347,136 --a------ C:\WINDOWS\system32\hypertrm.dll
2007-03-02 11:41 343,040 --a------ C:\WINDOWS\system32\mspaint.exe
2007-03-02 11:41 33,792 --a------ C:\WINDOWS\system32\regini.exe
2007-03-02 11:41 295,424 --a------ C:\WINDOWS\system32\termsrv.dll
2007-03-02 11:41 25,600 --a------ C:\WINDOWS\system32\comaddin.dll
2007-03-02 11:41 25,088 --a------ C:\WINDOWS\system32\mtxlegih.dll
2007-03-02 11:41 227,840 --a------ C:\WINDOWS\system32\avtapi.dll
2007-03-02 11:41 225,792 --a------ C:\WINDOWS\system32\catsrv.dll
2007-03-02 11:41 22,016 --a------ C:\WINDOWS\system32\qwinsta.exe
2007-03-02 11:41 21,896 --a------ C:\WINDOWS\system32\drivers\tdtcp.sys
2007-03-02 11:41 20,992 --a------ C:\WINDOWS\system32\msg.exe
2007-03-02 11:41 20,480 --a------ C:\WINDOWS\system32\qprocess.exe
2007-03-02 11:41 20,480 --a------ C:\WINDOWS\system32\mtxdm.dll
2007-03-02 11:41 19,968 --a------ C:\WINDOWS\system32\rdpsnd.dll
2007-03-02 11:41 183,808 --a------ C:\WINDOWS\system32\accwiz.exe
2007-03-02 11:41 161,280 --a------ C:\WINDOWS\system32\msdtcuiu.dll
2007-03-02 11:41 16,896 --a------ C:\WINDOWS\system32\tsshutdn.exe
2007-03-02 11:41 16,896 --a------ C:\WINDOWS\system32\qappsrv.exe
2007-03-02 11:41 16,384 --a------ C:\WINDOWS\system32\tskill.exe
2007-03-02 11:41 16,384 --a------ C:\WINDOWS\system32\avmeter.dll
2007-03-02 11:41 15,872 --a------ C:\WINDOWS\system32\rwinsta.exe
2007-03-02 11:41 15,872 --a------ C:\WINDOWS\system32\cdmodem.dll
2007-03-02 11:41 15,360 --a------ C:\WINDOWS\system32\logoff.exe
2007-03-02 11:41 147,968 --a------ C:\WINDOWS\system32\rdchost.dll
2007-03-02 11:41 147,456 --a------ C:\WINDOWS\system32\comsnap.dll
2007-03-02 11:41 140,800 --a------ C:\WINDOWS\system32\sessmgr.exe
2007-03-02 11:41 14,848 --a------ C:\WINDOWS\system32\tsdiscon.exe
2007-03-02 11:41 14,848 --a------ C:\WINDOWS\system32\tscon.exe
2007-03-02 11:41 14,848 --a------ C:\WINDOWS\system32\shadow.exe
2007-03-02 11:41 139,528 --a------ C:\WINDOWS\system32\drivers\rdpwd.sys
2007-03-02 11:41 138,752 --a------ C:\WINDOWS\system32\sndvol32.exe
2007-03-02 11:41 131,584 --a------ C:\WINDOWS\system32\sndrec32.exe
2007-03-02 11:41 13,824 --a------ C:\WINDOWS\system32\rdsaddin.exe
2007-03-02 11:41 126,976 --a------ C:\WINDOWS\system32\mshearts.exe
2007-03-02 11:41 123,392 --a------ C:\WINDOWS\system32\mplay32.exe
2007-03-02 11:41 12,040 --a------ C:\WINDOWS\system32\drivers\tdpipe.sys
2007-03-02 11:41 119,808 --a------ C:\WINDOWS\system32\winmine.exe
2007-03-02 11:41 114,688 --a------ C:\WINDOWS\system32\calc.exe
2007-03-02 11:41 110,080 --a------ C:\WINDOWS\system32\clbcatex.dll
2007-03-02 11:41 11,776 --a------ C:\WINDOWS\system32\xolehlp.dll
2007-03-02 11:41 11,264 --a------ C:\WINDOWS\system32\icaapi.dll
2007-03-02 11:41 102,912 --a------ C:\WINDOWS\system32\clipbrd.exe
2007-03-02 11:41 1,267,200 --a------ C:\WINDOWS\system32\comsvcs.dll
2007-03-02 11:41 1,161 --a------ C:\WINDOWS\system32\usrlogon.cmd
2007-03-02 11:41 <DIR> d-------- C:\WINDOWS\system32\MsDtc
2007-03-02 11:41 <DIR> d-------- C:\WINDOWS\system32\Com
2007-03-02 11:41 <DIR> d-------- C:\WINDOWS\Registration
2007-03-02 11:41 <DIR> d-------- C:\Program Files\Windows NT
2007-03-02 11:41 <DIR> d-------- C:\Program Files\Online Services
2007-03-02 11:41 <DIR> d-------- C:\Program Files\MSN Gaming Zone
2007-03-02 11:41 <DIR> d-------- C:\Program Files\Messenger
2007-03-02 11:40 58,880 --a------ C:\WINDOWS\system32\licwmi.dll
2007-03-02 11:40 56,320 --a------ C:\WINDOWS\system32\servdeps.dll
2007-03-02 11:40 185,344 --a------ C:\WINDOWS\system32\cmprops.dll
2007-03-02 11:40 17,408 --a------ C:\WINDOWS\system32\mmfutil.dll
2007-03-02 11:39 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys
2007-03-02 11:39 196,864 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys
2007-03-02 06:33 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2007-03-02 06:33 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2007-03-02 06:33 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2007-03-02 06:33 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2007-03-02 06:33 57,472 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2007-03-02 06:33 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2007-03-02 06:33 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2007-03-02 06:33 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2007-03-02 06:33 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2007-03-02 06:33 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2007-03-02 06:33 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2007-03-02 06:33 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2007-03-02 06:33 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2007-03-02 06:32 74,240 --a------ C:\WINDOWS\system32\usbui.dll
2007-03-02 06:32 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2007-03-02 06:32 6,400 --a------ C:\WINDOWS\system32\drivers\enum1394.sys
2007-03-02 06:32 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2007-03-02 06:32 2,944 --a------ C:\WINDOWS\system32\drivers\msmpu401.sys
2007-03-02 06:32 145,792 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2007-03-02 06:32 10,624 --a------ C:\WINDOWS\system32\drivers\gameenum.sys
2007-03-02 06:31 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll
2007-03-02 06:31 7,168 -ra------ C:\WINDOWS\system32\kbdcz.dll
2007-03-02 06:31 6,656 -ra------ C:\WINDOWS\system32\kbdycl.dll
2007-03-02 06:31 6,656 -ra------ C:\WINDOWS\system32\kbdsl1.dll
2007-03-02 06:31 6,656 -ra------ C:\WINDOWS\system32\kbdsl.dll
2007-03-02 06:31 6,656 -ra------ C:\WINDOWS\system32\kbdpl.dll
2007-03-02 06:31 6,656 -ra------ C:\WINDOWS\system32\kbdhu.dll
2007-03-02 06:31 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll
2007-03-02 06:31 6,656 -ra------ C:\WINDOWS\system32\kbdcz2.dll
2007-03-02 06:31 6,656 -ra------ C:\WINDOWS\system32\kbdcz1.dll
2007-03-02 06:31 6,656 -ra------ C:\WINDOWS\system32\kbdcr.dll
2007-03-02 06:31 6,656 -ra------ C:\WINDOWS\system32\KBDAL.DLL
2007-03-02 06:31 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll
2007-03-02 06:31 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll
2007-03-02 06:31 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll
2007-03-02 06:31 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll
2007-03-02 06:31 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll
2007-03-02 06:31 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll
2007-03-02 06:31 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll
2007-03-02 06:31 5,632 -ra------ C:\WINDOWS\system32\kbdro.dll
2007-03-02 06:31 5,632 -ra------ C:\WINDOWS\system32\kbdpl1.dll
2007-03-02 06:31 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll
2007-03-02 06:31 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll
2007-03-02 06:31 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll
2007-03-02 06:31 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll
2007-03-02 06:31 5,632 -ra------ C:\WINDOWS\system32\kbdhu1.dll
2007-03-02 06:31 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll
2007-03-02 06:31 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll
2007-03-02 06:31 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll
2007-03-02 06:31 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll
2007-03-02 06:31 <DIR> dr------- C:\Program Files
2007-03-02 06:31 <DIR> d--hs---- C:\WINDOWS\Installer
2007-03-02 06:31 <DIR> d-------- C:\Program Files\Common Files\SpeechEngines
2007-03-02 06:31 <DIR> d-------- C:\Program Files\Common Files\ODBC
2007-03-02 06:30 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL
2007-03-02 06:30 9,008 --a------ C:\WINDOWS\system\VER.DLL
2007-03-02 06:30 85,020 --a------ C:\WINDOWS\system32\dgsetup.dll
2007-03-02 06:30 82,944 --a------ C:\WINDOWS\system\OLECLI.DLL
2007-03-02 06:30 8,704 --a------ C:\WINDOWS\system32\batt.dll
2007-03-02 06:30 74,752 --a------ C:\WINDOWS\system32\storprop.dll
2007-03-02 06:30 69,584 --a------ C:\WINDOWS\system\AVICAP.DLL
2007-03-02 06:30 69,120 --a------ C:\WINDOWS\NOTEPAD.EXE
2007-03-02 06:30 68,768 --a------ C:\WINDOWS\system\MMSYSTEM.DLL
2007-03-02 06:30 5,120 --a------ C:\WINDOWS\system\SHELL.DLL
2007-03-02 06:30 32,816 --a------ C:\WINDOWS\system\COMMDLG.DLL
2007-03-02 06:30 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-03-02 06:30 24,064 --a------ C:\WINDOWS\system\OLESVR.DLL
2007-03-02 06:30 19,200 --a------ C:\WINDOWS\system\TAPI.DLL
2007-03-02 06:30 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll
2007-03-02 06:30 15,360 --a------ C:\WINDOWS\TASKMAN.EXE
2007-03-02 06:30 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-03-02 06:30 126,912 --a------ C:\WINDOWS\system\MSVIDEO.DLL
2007-03-02 06:30 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys
2007-03-02 06:30 109,456 --a------ C:\WINDOWS\system\AVIFILE.DLL
2007-03-02 06:30 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll
2007-03-02 06:30 <DIR> dr------- C:\DOCUME~1\ALLUSE~1\Documents
2007-03-02 06:30 <DIR> d--hs---- C:\System Volume Information
2007-03-02 06:30 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2007-03-02 06:30 <DIR> d-------- C:\WINDOWS\system32\CatRoot
2007-03-02 06:30 <DIR> d-------- C:\Documents and Settings
2007-03-02 06:23 <DIR> dr-hsc--- C:\WINDOWS\system32\dllcache
2007-03-02 06:23 <DIR> dr--s---- C:\WINDOWS\Fonts
2007-03-02 06:23 <DIR> dr------- C:\WINDOWS\Web
2007-03-02 06:23 <DIR> d--h----- C:\WINDOWS\inf
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\WinSxS
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\twain_32
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\wins
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\wbem
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\usmt
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\spool
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\ShellExt
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\Setup
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\ras
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\oobe
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\npp
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\mui
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\inetsrv
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\IME
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\icsxml
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\ias
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\export
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\drivers\etc
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\drivers\disdn
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\drivers
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\dhcp
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\config
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\3com_dmi
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\3076
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\2052
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\1054
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\1042
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\1041
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\1037
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\1033
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\1031
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\1028
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32\1025
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system32
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\system
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\security
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\Resources
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\repair
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\Provisioning
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\PeerNet
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\pchealth
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\mui
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\msapps
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\msagent
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\Media
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\java
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\ime
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\Help
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\ehome
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\Driver Cache
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\Debug
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\Cursors
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\Connection Wizard
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\Config
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\AppPatch
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS\addins
2007-03-02 06:23 <DIR> d-------- C:\WINDOWS
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-03-02 06:30 62 --ahs---- C:\DOCUME~1\JAM\APPLIC~1\desktop.ini
2007-01-08 20:01 17408 --a------ C:\WINDOWS\system32\corpol.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"avgnt"="\"C:\\Program Files\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
SafeBoot registry key needs to be repaired. This machine cannot enter Safe Mode.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{359ee1e9-c8d9-11db-9bba-0011d8029acd}]
Shell\AutoRun\command F:\autoplay.exe
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c1667a9e-d177-11db-9bee-0011d8029acd}]
Shell\AutoRun\command F:\autoplay.exe
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-03-23 14:02:29
C:\ComboFix2.txt ... 07-03-21 16:25